28 Sep
|
KPMG Assurance and Consulting Services
|
Noida
28 Sep
KPMG Assurance and Consulting Services
Noida
a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; }
Job Summary
We are seeking a skilled Cyber Security professional with hands-on experience in the Microsoft Security Stack, specifically Microsoft Sentinel (Azure Sentinel) and Microsoft Defender for Endpoint (MDE). The candidate will be responsible for monitoring, investigating, and responding to security incidents, developing detection use cases, and enhancing the organization's security posture through proactive threat hunting and security operations.
Key Responsibilities
- Monitor and investigate security alerts and incidents using Microsoft Sentinel and Microsoft Defender for Endpoint (MDE).
- Perform threat hunting activities and analyze logs to identify potential security threats.
- Create, tune, and maintain analytics rules, workbooks, and automation playbooks in Microsoft Sentinel.
- Conduct incident triage, containment, eradication, and recovery activities.
- Analyze endpoint security events, malware detections, suspicious activities, and attack patterns.
- Develop and optimize KQL (Kusto Query Language) queries for log analysis and threat detection.
- Integrate security data sources with Microsoft Sentinel and maintain log ingestion health.
- Collaborate with internal teams to remediate vulnerabilities and security findings.
- Prepare incident reports, root cause analysis, and security recommendations.
- Support SOC operations and contribute to continuous improvement initiatives.
Required Skills
- 2 years of experience in Cyber Security / SOC Operations.
- Hands-on experience with Microsoft Sentinel (Azure Sentinel).
- Hands-on experience with Microsoft Defender for Endpoint (MDE).
- Solid understanding of SIEM, EDR, incident response, and threat detection concepts.
- Experience with KQL (Kusto Query Language).
- Knowledge of Windows Security, Endpoint Security, and Microsoft Security ecosystem.
- Familiarity with MITRE ATT&CK; framework and cyber kill chain.
- Valuable understanding of security monitoring, log analysis, and alert triage.
- Experience in handling phishing, malware, ransomware, and endpoint-related security incidents.
Preferred Skills
- Experience with Microsoft Defender XDR suite.
- Knowledge of Azure Security, Microsoft Defender for Cloud, and Identity Security.
- Exposure to SOAR automation and Logic Apps.
- Security certifications such as SC-200, AZ-500, Security , CEH, or equivalent.
📌 SIEM Admin - Microsoft Sentinel, MDE , MDC (Noida)
🏢 KPMG Assurance and Consulting Services
📍 Noida